Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jbeda
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
20 ms
·
61.
▲
by
jbeda
11y ago
I agree that they are orthogonal but I'm not convinced that they are the right tool for the job. They can do all sorts of things above and beyond what is needed. Those capabilities come at a cost. For instance, they also manage thin
62.
▲
by
jbeda
11y ago
Agreed -- but how do you figure out which packages are in an image without cracking that image? Quick -- what version of OpenSSL is in the golang Docker images? ( https://registry.hub.docker.com/_/golang/ ). Short
63.
▲
by
jbeda
11y ago
I think this is really orthogonal. Puppet/Chef/Ansible/Salt all help to configure an environment and work with the native package manager for the OS. What I'm suggesting here is to instead create a new package manager
64.
▲
by
jbeda
11y ago
Thanks for the pointers -- I'll dig in to those to get more ideas. Also agree that config-as-package is part of this too. As for statically linked binaries -- this solves some of it but not all. Still hard to figure out which version
65.
▲
by
jbeda
11y ago
Immutable images are the name of the game. Any sort of surgical update to image A would result in image A-prime. Any sort of orchestration system will help to run containers and will know what images you are running but not which packag
66.
▲
by
jbeda
11y ago
I looked closely at Nix and there is a lot to like there. The thing that turned me off is that it is just too complex. Going from something like Dockerfiles to Nix is just a huge leap. Example: http://sandervanderburg.blogspot.
67.
▲
by
jbeda
11y ago
Happy to answer questions and brainstorm ideas here.
68.
▲
Thoughts on a Container Native Package System
(eightypercent.net)
20 points
by
jbeda
11y ago
|
23 comments
69.
▲
by
jbeda
11y ago
I suggest you also look at GCE for network performance. It is something that the Google networking team has been working hard on and, because of the unique network fabric at Google, should scale to lots of VMs. Also, you can get equivalent
70.
▲
by
jbeda
11y ago
Kubernetes uses Docker (or now rkt) to do the actual containing. The focus is on scheduling and managing lots of containers. You may run O(10) containers on a single machine. When you run O(10k)+ containers in a cluster you need new tools
71.
▲
Super easy mobile app localization from Colatris and Unbabel
(blog.unbabel.com)
1 points
by
jbeda
12y ago
|
0 comments
72.
▲
by
jbeda
12y ago
I remember when we first did this on IE5.5. It fell out naturally from some improvements to the rendering system and a dev (forgot his name! Don?) prototyped it to show off his new subsystem. It eventually got supported because, at the time
73.
▲
by
jbeda
12y ago
I'm late to this thread, but hopefully I can add some value. I've recently been through this for my own personal email. I have a domain with some interesting rewrites to the address that I forward to GMail. I put together my set
74.
▲
New Google Container Registry for Docker Images
(cloud.google.com)
9 points
by
jbeda
12y ago
|
0 comments
75.
▲
by
jbeda
12y ago
Actually, this is intentional. Pre-andromeda, we hit ARP caching issues when testing scale for GCE. The model to let the SDN figure out the other end (and stub out things like ARP) was carried forward with Andromeda. (I'm the origina
76.
▲
by
jbeda
12y ago
Update: the discovery endpoint is pretty simple and now documented: https://github.com/docker/swarm/blob/master/discovery/README...
77.
▲
by
jbeda
12y ago
You are right -- perhaps I'm being unfair. It is Docker's right to run their project as they see fit. I'm glad to see the new projects (swarm, at least) layered on top of Docker. It is good to see those sink/swim on th
78.
▲
by
jbeda
12y ago
The advisory board is just that -- advisory. It has no teeth. All approval of anything goes through Docker.com/Solomon. It is worth reading through the notes from the last/only meeting: https://docs.google.com/do
79.
▲
by
jbeda
12y ago
The advisory board is just that -- advisory. It has absolutely no teeth. The open source project is 100% owned by Docker, Inc. Solomon believes strongly in a "firewall" between OSS Docker and Docker, Inc -- but it breaks down i
80.
▲
by
jbeda
12y ago
We aren't doing multi-tenant in a VM. Instead, each user/account/project has their own set of VMs implementing the cluster. My view is that the surface area for cgroups/kernel namespaces is just too large and isn't
81.
▲
by
jbeda
12y ago
Stable production ready GKE will gate on Kubernetes. Our Kubernetes roadmap is here: https://github.com/GoogleCloudPlatform/kubernetes/blob/maste... We are driving aggressively here. I hate to put a date on
82.
▲
by
jbeda
12y ago
Elastic Beanstalk is a VM centric management framework. Kubernetes and GKE operate at a different level. It is an API for being able to schedule and manage containers instead of VMs. At this point, k8s/GKE doesn't have an idea of
83.
▲
by
jbeda
12y ago
Correct -- we don't do multi-tenant on the same VM. The security just isn't there in our minds. We don't do rebalancing/rescheduling/repacking yet. Those are the types of things that we will be working on moving f
84.
▲
by
jbeda
12y ago
GCE doesn't support nested virtualization. But if you are running Kubernetes on bare metal, there is no reason you couldn't map in /dev/kvm and have k8s run VMs for you. I haven't done it though :)
85.
▲
by
jbeda
12y ago
Essentially that is the case. If you just want to launch a static set of containers on a specific VM, you can use our Container VM image -- https://cloud.google.com/compute/docs/containers/container_v... . Kub
86.
▲
by
jbeda
12y ago
It can be used as both. As we build out better resource isolation and QoS, you'll be able to run mixed workload on the same hardware/VMs and use "every part of the animal".
87.
▲
by
jbeda
12y ago
Right now, it isn't plumbed in but it is on the roadmap. Either (a) you have network based block device and the master/manager maps that to a machine dynamically as the container get scheduled or (b) you constrain the containers t
88.
▲
by
jbeda
12y ago
The TechCrunch article is incorrect. While it is still an early service, there is no whitelist.
89.
▲
by
jbeda
12y ago
More info/docs here: https://cloud.google.com/container-engine/ I'm on the Kubernetes/GKE team and happy to answer any questions you all might have. We also all hang out on IRC at #google-containers on f
90.
▲
by
jbeda
12y ago
I wrote some golang code to generate Penrose P2 tiling in svg. Plan is to laser cut these but haven't had a chance yet. Code: https://github.com/jbeda/penrose-svg
More ›